Does NDES service account will support for kerberos AES 256 bit encryption?

Bab bab 6 Reputation points
2022-06-23T03:18:27.15+00:00

Does NDES (Network Device Enrollment Service) service account will support for Kerberos AES 256 bit encryption? if we enable AES256 encryption will it cause any problem for Intune deployment?

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Microsoft Security | Intune | Configuration
Windows for business | Windows Server | User experience | Other
0 comments No comments
{count} vote

3 answers

Sort by: Most helpful
  1. risolis 8,741 Reputation points
    2022-06-23T03:44:17.037+00:00

    Hello @Bab bab

    Thank you for your post.

    I would suggest you to go through the following articles shown below:

    https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/ndes-security-best-practices/ba-p/2832619

    https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/intune-enrollment-options-for-end-entity-certificates/ba-p/2498646

    Looking forward to your feedback,

    Best Regards,

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    1 person found this answer helpful.
    0 comments No comments

  2. Crystal-MSFT 53,991 Reputation points Microsoft External Staff
    2022-06-24T06:02:40.07+00:00

    @Bab bab , In the first article which ricardosolisvillegas provided, it says that the NDES account as gMSA or Domain user accounts: enforce AES encryption.

    Then I go to do test in my SCEP environment with NDES, enable "This account supports Kerberos AES 256 bit encryption" on NDES service account. And find the SCEP certificate request from Intune profile can still works. I can still get the certificate.
    214569-image.png
    So I think it supports.

    Hope it can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


  3. Limitless Technology 39,931 Reputation points
    2022-06-24T11:36:31.067+00:00

    Hi there,

    I suspect that it is not recommended to use the configuration as you have stated.

    NDES gets involved in verifying the certificate request, as it is acting as a Registration Authority (RA) and an endpoint for SCEP-based communication.

    This article describes the best practices, location, values, and security considerations for the Network security: Configure encryption types allowed for Kerberos security policy setting.
    https:// learn.microsoft.com/en-us/windows/security/threat-protection/security-policy-settings/network-security-configure-encryption-types-allowed-for-kerberos

    ---------------------------------------------------------------------------------------------------------------------------------------------------------

    --If the reply is helpful, please Upvote and Accept it as an answer--

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.